Worm.IM.Sohanad is a worm that spreads itself via Yahoo Messenger and can infect all the contacts present in your Yahoo Messenger Contacts List, by sending them a text message that can contain a malicious HTTP link pushing the users to download the worm. Its also possible for the worm to send a HTTP link that contains 0-day exploits for common web browsers, and in this case it is only necessary for users to visit the malicious link to become a victim.

The worm can disable certain Windows functionalities and, in some cases, it can hijack the browser Internet Explorer homepage and other registry keys. The worm is also used for download other malware or other programs that can steal credit cards and personal information.

It is also able to spread itself not only by Yahoo Messengers but also by infecting removable devices such as USB flash and hard drives. The worm can copy itself on the removable device and using the file autorun.ini it can infect every computer where will be inserted the removable device and that have the Autorun option enabled.